Suspicious
Suspect

77cc439ad3bb3e5db8107fc598453a12

PE Executable
|
MD5: 77cc439ad3bb3e5db8107fc598453a12
|
Size: 465.41 KB
|
application/x-dosexec


Print
Summary by MalvaGPT
Characteristics

Symbol Ofbuscation Score

High

Hash
Hash Value
MD5
77cc439ad3bb3e5db8107fc598453a12
Sha1
057ae750c8022111e3466189184ea3039f50201d
Sha256
c3105cdaac7f7886aedf30ba4da177472786d9bca22f4a787eff30e18a9c7b3b
Sha384
b7cf4d1ff39e622d7e6ea3342efc10de39f753390b740e0744b812f48f9ff7a20f304f2922b16ff2f6340daef4eeeaaa
Sha512
e05c041b6f8770520445b48ecd6ed99828e10503743bb23d07c4a805f80a57650b5237fbd5aadf7c34769ab9ca4186d3ad3d0990c81390f634f250fa3a404d44
SSDeep
6144:r9AejdBEh/drh3EpWxorPKeV7moIzfKmXthcTojHM4h8KHVsDZYzbGBMiEUfIm:BAph/dzCGfKmXjKot8UCebFPm
TLSH
9BA4BE55D9D2CD52DE552FB2C53289704073BD6816F2F78BA8CA38B627F33E1042A85B

PeID

.NET executable
Microsoft Visual C# / Basic .NET
Microsoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL
Microsoft Visual C# v7.0 / Basic .NET
Microsoft Visual Studio .NET
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0002
ID:0
ID:0003
ID:0
ID:0004
ID:0
ID:0005
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Module Name

server1.exe

Full Name

server1.exe

EntryPoint

System.Void server.Module2::main()

Scope Name

server1.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

server1

Assembly Version

2.8.7.9

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.8

Total Strings

32

Main Method

System.Void server.Module2::main()

Main IL Instruction Count

83

Main IL

nop <null> ldc.i4 512610357 stloc.3 <null> ldc.i4 339632463 ldloc.3 <null> not <null> not <null> sub <null> not <null> dup <null> stloc.2 <null> ldc.i4.7 <null> rem.un <null> switch dnlib.DotNet.Emit.Instruction[] br IL_0112: ret ldloc.1 <null> ldsfld System.Byte[] server.Module2::Bytes call System.Object server.Module2::_601FD481319C4FED_() call System.Object server.Module2::_E3F6D30ABDE34CC7_(System.Object) call System.String server.Module2::_E8559FEBD3EC4629_(System.Object) call System.Boolean server.Module2::_0D51448BB10F4591_(System.Object,System.Byte[],System.String) pop <null> ldc.i4 -513552232 stloc.s V_8 ldloc.2 <null> ldc.i4 -852714 mul <null> ldloc.s V_8 xor <null> br.s IL_0006: stloc.3 ldloc.0 <null> ldsfld System.Byte[] server.Module2::Bytes call System.Object server.Module2::_601FD481319C4FED_() call System.Object server.Module2::_E3F6D30ABDE34CC7_(System.Object) call System.String server.Module2::_E8559FEBD3EC4629_(System.Object) call System.Boolean server.Module2::_B6DBC024370647AE_(System.Object,System.Byte[],System.String) pop <null> ldc.i4 35616131 stloc.s V_6 ldloc.2 <null> ldc.i4 -364968 mul <null> ldloc.s V_6 xor <null> br IL_0006: stloc.3 call System.Object server.Module2::_12F96CDF56B3437C_() stloc.1 <null> ldc.i4 -1418820452 stloc.s V_7 ldloc.2 <null> ldc.i4 -87245 mul <null> ldloc.s V_7 xor <null> br IL_0006: stloc.3 call System.Object server.Module2::_30668BA4F7764077_() stloc.0 <null> ldc.i4 -1741388887 stloc.s V_5 ldloc.2 <null> ldc.i4 -82713 mul <null> ldloc.s V_5 xor <null> br IL_0006: stloc.3 call System.String server.Module2::_1D3345B53A234AD0_() ldc.i4 -1841576041 br.s IL_00DE: call System.String <Module>::_66F0EA7F5F4444A9_<System.String>(System.IntPtr) call System.String <Module>::_66F0EA7F5F4444A9_<System.String>(System.IntPtr) call System.String server.Module2::_F5C4AD2753F84D71_(System.String,System.String) stsfld System.String server.Module2::Hex ldsfld System.String server.Module2::Hex call System.Byte[] server.Module2::_E57D7E4C5F5D4D38_(System.String) stsfld System.Byte[] server.Module2::Bytes ldc.i4 1096533760 stloc.s V_4 ldloc.2 <null> ldc.i4 -931231 mul <null> ldloc.s V_4 xor <null> br IL_0006: stloc.3 ret <null>

Module Name

server1.exe

Full Name

server1.exe

EntryPoint

System.Void server.Module2::main()

Scope Name

server1.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

server1

Assembly Version

2.8.7.9

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.8

Total Strings

32

Main Method

System.Void server.Module2::main()

Main IL Instruction Count

83

Main IL

nop <null> ldc.i4 512610357 stloc.3 <null> ldc.i4 339632463 ldloc.3 <null> not <null> not <null> sub <null> not <null> dup <null> stloc.2 <null> ldc.i4.7 <null> rem.un <null> switch dnlib.DotNet.Emit.Instruction[] br IL_0112: ret ldloc.1 <null> ldsfld System.Byte[] server.Module2::Bytes call System.Object server.Module2::_601FD481319C4FED_() call System.Object server.Module2::_E3F6D30ABDE34CC7_(System.Object) call System.String server.Module2::_E8559FEBD3EC4629_(System.Object) call System.Boolean server.Module2::_0D51448BB10F4591_(System.Object,System.Byte[],System.String) pop <null> ldc.i4 -513552232 stloc.s V_8 ldloc.2 <null> ldc.i4 -852714 mul <null> ldloc.s V_8 xor <null> br.s IL_0006: stloc.3 ldloc.0 <null> ldsfld System.Byte[] server.Module2::Bytes call System.Object server.Module2::_601FD481319C4FED_() call System.Object server.Module2::_E3F6D30ABDE34CC7_(System.Object) call System.String server.Module2::_E8559FEBD3EC4629_(System.Object) call System.Boolean server.Module2::_B6DBC024370647AE_(System.Object,System.Byte[],System.String) pop <null> ldc.i4 35616131 stloc.s V_6 ldloc.2 <null> ldc.i4 -364968 mul <null> ldloc.s V_6 xor <null> br IL_0006: stloc.3 call System.Object server.Module2::_12F96CDF56B3437C_() stloc.1 <null> ldc.i4 -1418820452 stloc.s V_7 ldloc.2 <null> ldc.i4 -87245 mul <null> ldloc.s V_7 xor <null> br IL_0006: stloc.3 call System.Object server.Module2::_30668BA4F7764077_() stloc.0 <null> ldc.i4 -1741388887 stloc.s V_5 ldloc.2 <null> ldc.i4 -82713 mul <null> ldloc.s V_5 xor <null> br IL_0006: stloc.3 call System.String server.Module2::_1D3345B53A234AD0_() ldc.i4 -1841576041 br.s IL_00DE: call System.String <Module>::_66F0EA7F5F4444A9_<System.String>(System.IntPtr) call System.String <Module>::_66F0EA7F5F4444A9_<System.String>(System.IntPtr) call System.String server.Module2::_F5C4AD2753F84D71_(System.String,System.String) stsfld System.String server.Module2::Hex ldsfld System.String server.Module2::Hex call System.Byte[] server.Module2::_E57D7E4C5F5D4D38_(System.String) stsfld System.Byte[] server.Module2::Bytes ldc.i4 1096533760 stloc.s V_4 ldloc.2 <null> ldc.i4 -931231 mul <null> ldloc.s V_4 xor <null> br IL_0006: stloc.3 ret <null>

77cc439ad3bb3e5db8107fc598453a12 (465.41 KB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙